OXLOADER: new loader evading detection to drop infostealer

June 19, 2026, 8:39 a.m.

Description

A previously undocumented Windows loader designated as OXLOADER delivers the CASTLESTEALER infostealer through malicious Google Ads campaigns, achieving remarkably low detection rates. The loader employs multiple obfuscation layers including control-flow flattening, opaque predicates, and mixed Boolean-Arithmetic techniques, along with self-modifying decryption stubs and abuse of the Windows .reloc section for shellcode staging. Distribution occurs via malvertising impersonating Node.js installations, redirecting victims through intermediary domains to Storj-hosted batch scripts. The loader implements five anti-VM and language checks, including CIS-region and Russian-language exclusions, suggesting a financially motivated Russian-speaking threat actor. OXLOADER uses DonutLoader to deliver the .NET-based CASTLESTEALER payload in memory, evading traditional detection mechanisms through deliberate engineering choices.

Date

  • Created: June 19, 2026, 12:03 a.m.
  • Published: June 19, 2026, 12:03 a.m.
  • Modified: June 19, 2026, 8:39 a.m.

Indicators

  • de4f51649ec1a33071854aefe93ffb3fc225e19f802d8dd914676dd5dfef2615
  • c85f2765a6c3c3f3907c17e57df12f8f68826f74bff3bbfd272af50666d065fe
  • 39019279686c820c3af5684012a0085a7e2109f612c9fab886dd0577ace5b5c6
  • fdfc7831e5c24cfa80152860dfe8c056ba079f7df1393bf6bb7b18ed974eda37
  • 9a9939dff297997732aaade9b243d695632cbd64033c5fbcb9de3d09b7e6c28d
  • 4ec9d9d4d10ad78fc6d7bda7cb17d52984878ccd2dd4302fd1cef152313b9741
  • https://link.storjshare.io/raw/jv5uebuqwzfpmtahj34q753ptykq/node/BATPackageBulderSetup.bat
  • http://app.miloyannopoulos.com/download?subid1=download
  • http://app.miloyannopoulos.com/download
  • https://link.storjshare.io/raw/jvsmdybqmvwep2oawbobp6ub7aza/node/node-v24.15.0-x64-86.exe
  • http://link.storjshare.io/raw/jwwvr4oskkkjsgevt774ta62ehya/ruslan/aBsvwbdas.exe
  • http://link.storjshare.io/raw/jux4e4ky5mruo4jkxsssp42sau4q/ruslan/BATPackageBuilderSetup.bat

Attack Patterns

  • DonutLoader
  • CASTLESTEALER
  • OXLOADER

Additional Informations

  • node-js.prentiva99.info
  • United States of America